Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Peer VC Controls Policy' = 'C:\vdmyjdxwsnpvu\qlbcbyjdxir.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\Identity Media Office Intelligent] 'ImagePath' = 'C:\vdmyjdxwsnpvu\qlbcbyjdxir.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\Identity Media Office Intelligent] 'Start' = '00000002'
- 'C:\vdmyjdxwsnpvu\jlccwqted.exe' "c:\vdmyjdxwsnpvu\qlbcbyjdxir.exe"
- 'C:\vdmyjdxwsnpvu\qlbcbyjdxir.exe'
- 'C:\vdmyjdxwsnpvu\oaef2vhpvqa3pmvqcq.exe'
- C:\vdmyjdxwsnpvu\qlbcbyjdxir.exe
- C:\vdmyjdxwsnpvu\jlccwqted.exe
- C:\vdmyjdxwsnpvu\h7kqrs
- %WINDIR%\vdmyjdxwsnpvu\vnhhf9cxhif
- C:\vdmyjdxwsnpvu\vnhhf9cxhif
- C:\vdmyjdxwsnpvu\oaef2vhpvqa3pmvqcq.exe
- C:\vdmyjdxwsnpvu\jlccwqted.exe
- C:\vdmyjdxwsnpvu\qlbcbyjdxir.exe
- C:\vdmyjdxwsnpvu\oaef2vhpvqa3pmvqcq.exe
- %WINDIR%\vdmyjdxwsnpvu\vnhhf9cxhif
- %WINDIR%\vdmyjdxwsnpvu\vnhhf9cxhif
- '11#.#18.187.28':42065
- '77.##8.205.139':22969
- '74.#5.64.25':22739
- '86.##5.10.227':45279
- '41.##.10.183':48405
- '18#.#39.139.100':37599
- '21#.#07.110.82':26314
- '12#.#60.123.173':36805
- '18#.#0.243.3':25741
- '77.##7.13.68':30018
- '22#.#1.110.45':48008
- ClassName: 'Shell_TrayWnd' WindowName: ''